Extension WordPress

Vulnérabilités PeachPay , Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)

Cette page rassemble les failles publiées pour PeachPay , Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI), leurs plages de versions affectées et les correctifs signalés dans la base locale.

5Vulnérabilités
0Critiques
5Avec correctif
6,5CVSS maximal

Historique de sécurité

CVE et vulnérabilités de PeachPay , Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)

5 fiches

CVE-2026-9618 Moyenne · 4,3
PeachPay , Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)

PeachPay <= 1.120.46 – Cross-Site Request Forgery to Stripe Unlink

The PeachPay , Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.120.46. This is due to missing or…

Versions affectées

*-1.120.46

Correctif

1.120.47

Publication

27/05/2026

CVE-2025-14978 Moyenne · 5,3
PeachPay , Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)

PeachPay , Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) <= 1.119.8 – Missing Authorization to Unauthenticated Order Status Modification

The PeachPay , Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability checks on the ConvesioPay webhook REST endpoint in all…

Versions affectées

*-1.119.8

Correctif

1.119.9

Publication

19/01/2026

CVE-2025-9463 Moyenne · 6,5
PeachPay , Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)

Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net <= 1.117.5 – Authenticated (Contributor+) SQL Injection via order_by Parameter

The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order_by’ parameter in all versions up to, and including, 1.117.5 due to insufficient escaping on…

Versions affectées

*-1.117.5

Correctif

1.117.6

Publication

09/09/2025

CVE-2025-58634 Moyenne · 5,3
PeachPay , Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)

PeachPay Payments <= 1.117.4 – Missing Authorization

The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.117.4. This…

Versions affectées

*-1.117.4

Correctif

1.117.5

Publication

03/09/2025

CVE-2024-11362 Moyenne · 6,1
PeachPay , Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)

Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net <= 1.112.0 – Reflected Cross-Site Scripting

The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to,…

Versions affectées

*-1.112.0

Correctif

1.113.0

Publication

22/11/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités